AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16968

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The GeoDirectory WordPress plugin prior to version 2.8.168 is vulnerable due to inadequate access controls on its user-search functionality, permitting any authenticated user with Contributor-level access or higher to access the email addresses of all registered users, including administrators. This exposure could lead to privacy breaches and targeted phishing attacks. WordPress site administrators and security teams should prioritize this vulnerability to protect user data and maintain compliance with data protection regulations.

CVE
CVE-2026-16968
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.